Updated zip packages fix a security vulnerability
Publication date: 14 Sep 2026Modification date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2018-13410
Description
zip test option (-T) command injection.
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used,
allows attackers to cause a denial of service (invalid free and
application crash) or possibly have unspecified other impact because of
an off-by-one error. (CVE-2018-13410)
References
SRPMS
10/core
- zip-3.0-17.1.mga10
9/core
- zip-3.0-14.1.mga9